NIST AI Agent Standards Initiative (CAISI): What It Means for AI Agents
What CAISI's AI Agent Standards Initiative covers, its three pillars, the 2026 timeline so far, and what enterprises should do now to prepare.

Rushali
NIST's Center for AI Standards and Innovation (CAISI) announced the AI Agent Standards Initiative on Feb. 17, 2026, as the U.S. government's inaugural program to advance the standardization of autonomous AI agents, their securing, authentication, and interoperability. The timing wasn't random. The current guidance on AI from NIST is designed for systems that generate text, code, or images that are sent for review by a human before any action is taken. It doesn't say much about systems that call APIs, execute multi-step plans, carry their own credentials, and have no human signed up at each step to carry the state across sessions, etc. CAISI's new program is NIST's attempt to catch up with agentic deployments before they manage to outpace the standards intended to control them. So what launched, what's on the horizon, and what to do now.
What is CAISI, and Why Did It Launch This Initiative?
CAISI is part of the NIST Information Technology Laboratory and serves as the agency's coordinating entity for AI standards on the domestic and international fronts. To understand why it introduced a dedicated agent initiative – not just a continuation of the guidance – one has to consider two factors: NIST's current library and the strategic decision to time it.
The Gap in NIST's Existing Frameworks (AI RMF 1.0 and AI 600-1)
NIST AI RMF 1.0 is a voluntary framework that consists of four functions: Govern, Map, Measure, and Manage. It predates the common use of tool-calling agents, and it views "AI risk" mostly as a characteristic of the model's outputs, such as bias, explainability, or even the reliability of a given output. In July 2024, NIST released its Generative AI Profile, AI 600-1, which furthered that thinking to generative-specific risks like confabulation and data memorization, but still made the assumption that these outputs are reviewed by a human before anything downstream occurs. Agents don't make that assumption. They call tools, chain operations across systems, and execute over extended sessions with no one human watching each step. That operating model was not intended for either AI RMF 1.0 or AI 600-1, that's what CAISI's new initiative is designed to fill.
The Geopolitical Framing: Standards Leadership, Not Just Safety
CAISI is a relatively new rebrand. Howard Lutnick, Commerce Secretary, renamed the former AI Safety Institute to the Center for AI Standards and Innovation, which now states that its focus will be innovation, competitiveness, and the actual reduction of security risks, in June 2025. The change is reflected explicitly in the Agent Standards Initiative itself, which NIST has defined as "to promote an ecosystem of industry-led standards, while maintaining U.S. leadership at the forefront of the technology. It's not just a matter of risk mitigation, but of geopolitical competition between a U.S.-led, industry-driven standards-setting process and the EU's more prescriptive regulatory process and China's centrally directed one. As part of its work, CAISI advocates on behalf of U.S. interests at international standards bodies such as ISO/IEC JTC 1/SC 42 to help ensure that foreign-drafted requirements do not set the world stage as the global standard for agentic AI.
The Three Strategic Pillars
The initiative was structured around three elements, each created in collaboration with NIST's Information Technology Laboratory and the National Science Foundation. These pillars address various drivers of trust in agent systems, and when taken together, they make sense of why NIST decided on convening, rather than issuing a one-size-fits-all standard, and invested in research.
Facilitating Industry-Led Standards
The first pillar is helping industry to create and shape agent standards and U.S. input into the international bodies that formalize them. Instead of developing an agent specification in-house, CAISI is seeking to serve as a convener, encouraging industry-led efforts on the standards development process for agent interoperability, and advocating for the United States to take a technical leadership role in the standards organizations that will be the ones to approve these standards.
Fostering Community-Led Protocols
The second pillar is to develop and sustain open-source protocols led by the community with agents. This is recognition of a reality: agent interoperability is what is happening now, and it is coming up from the bottom, not the top, via open protocols created and maintained by developer communities rather than government. CAISI's job here is not to compete with the community-led agent protocols that are being adopted, but rather to provide support for them as a steward.
Investing in Research (Agent Authentication and Identity Infrastructure)
The third pillar is the research progress on AI agent security and identity, which will facilitate new use cases and foster trusted adoption of AI agents. Here is where the program is most tangible. The NIST identity concept paper, released in February 2026 through the National Cybersecurity Center of Excellence, falls right in the middle of this pillar, suggesting adding the existing enterprise identity standards to autonomous agents, rather than developing a new agent-specific framework. It's the most unambiguous indication yet of the direction of agent authentication research: authenticating agents as workloads and not extensions of a human user's identity.
The 2026 Timeline So Far
It's not just a single announcement; it's a range of overlapping deliverables, comment windows, and sessions that began prior to the February launch and will follow it. It is important to realize that order of presentation is vital for everyone who has to make a decision about when to engage.
The January 2026 RFI and What It Asked
CAISI's groundwork started with a Request for Information, published in the Federal Register on January 8, 2026, under docket NIST-2025-0035. CAISI requested concrete examples, case studies, and recommendations on the current threat landscape of agent systems, existing mitigations and their gaps, measurement methodologies, and on securely developing agent systems. As NIST-2025-0035 closed March 9, 2026, it garnered formal responses from groups such as the OpenID Foundation and a coalition of industry financial services groups, BITS, the Bank Policy Institute, and the American Bankers Association, marking an early indication that identity federation and financial-sector risk management are in the early lead in industry's race for NIST's attention.
Comment Periods and Listening Sessions (March–April 2026)
The public comment period for AI agents in the RFI was open until March 9, but that didn't end the input gathering. In parallel, CAISI announced a series of virtual listening sessions beginning in April 2026 that will focus on practitioners in the healthcare, financial services, and education sectors to hear directly about enabling and inhibiting factors for AI and agent adoption in production. Any organization interested in joining these AI agent listening sessions was invited to submit its interest, as well as examples of successful and unsuccessful implementations, before March 31, 2026. The RFI and listening sessions are CAISI's two main mechanisms for developing CAISI guidelines and research agendas.
The Identity Concept Paper and What It Signals for Agent Authentication
The National Cybersecurity Center of Excellence released a concept paper, entitled Accelerating the Adoption of Software and AI Agent Identity and Authorization, alongside the RFI, on February 5, 2026, with the deadline for comments being April 2, 2026. It's remarkable because it's much more technical than any other aspect of the initiative to-date. The paper poses the problem with four focus areas: identification, authorization, auditing, and non-repudiation, and suggests leveraging existing mechanisms, not inventing new ones: OAuth 2.0 and its extension, OpenID Connect, the provisioning protocol SCIM, and the cryptographic workload attestation protocol SPIFFE/SPIRE. Preformalization, the direction is quite clear – agents will be identity objects distinct from other identities, auditable like other identities, but not subject to an entirely new identity model.
How This Relates to Other NIST and Industry Frameworks
The Agent Standards Initiative is not a substitute for the other work NIST has done on agents; it is in addition to it, and in fact many of the practitioner-driven frameworks that were filling the security agency gap before the move of CAISI are on a number of NIST's tracks.
NIST IR 8596 (Cyber AI Profile) as a Parallel Compliance Path
NIST IR 8596, the Cyber AI Profile, was published as a draft for public comment on December 16, 2025; the comment period will close on January 30, 2026. It aligns the AI-specific cybersecurity concerns with the six functions of the Cybersecurity Framework 2.0, across three focus areas: Securing AI system components against attack, defending with AI-enabled tools, and defending against AI-enabled attacks. Most importantly, it is an overlay and not intended to replace an existing security program - if an organization is already aligned with CSF 2.0, they need to find where agents and AI parts fill gaps in their existing program. IR 8596 is the most straightforward compliance-mapping partner to the newer Agent Standards Initiative for agent-heavy environments.
Where This Fits Alongside OWASP, MITRE ATLAS, and MAESTRO
Most of NIST's work is at the policy and standards level, with the technical detail being provided by practitioner-based frameworks that were developed ahead of NIST due to the lack of the federal rulemaking process. OWASP Top 10 for Agentic Applications builds on the previous OWASP LLM Top 10 with risks specific to autonomous systems such as goal hijacking, tool misuse, and memory/context poisoning. MITRE's ATLAS threat matrix can be complemented by a structured threat modeling framework across the layers of a multi-agent environment provided by the Cloud Security Alliance, MAESTRO. Few of these have the weight of regulatory authority, but references to them directly in the responses to the RFI from CAISI indicate that these will direct the technical content of any final NIST publication. That's the same layered thinking Akto's own attack matrix exemplifies, whereby there are risks to keep track of, such as tool poisoning, tool shadowing, and prompt injection by tool output, which are mapped to the input, execution, and output layers of an agent's workflow, and teams have a place to begin before the arrival of NIST's own overlays.
The Global Regulatory Backdrop
CAISI's initiative doesn't exist in isolation. Two other jurisdictions have progressed in the development of governance for agentic AI so far in 2026, and both at different paces and types of governance, and both provide a helpful backdrop to the current state of U.S. standards development.
Why the EU AI Act Doesn't Yet Define "Agentic AI Systems"
There is no specific provisions of the EU AI Act for agents. Nevertheless, autonomous agents are part of the general definition of an AI system provided in Article 3(1) of the Act, and are subject to the same risk tiers as other systems, depending on the use case, and not on the fact that they are autonomous. Article 50's transparency requirements hit agents dealing with people and/or creating content, but the EU AI Act agentic AI systems provisions do not have an independent legal definition, and EU officials and legal commentators are publicly acknowledging that the relationship between AI agents and the existing categories is ongoing and evolving. That creates a structural gap for any organization to relate the deployment of agents directly to the obligations of the Act.
Singapore's IMDA as an Early Mover
Singapore moved first. The Model AI Governance Framework for Agentic AI was introduced by the Infocomm Media Development Authority (IMDA) on 22 January 2026, which is the world's first governance framework created specifically for agentic systems. The Singapore IMDA agentic AI framework involves four key elements: upfront assessment and bounding of risk, meaningful human accountability, technical controls and processes, and end-user responsibility. Compliance is entirely voluntary, but they are still legally responsible for what their agents do. On May 20, 2026, IMDA updated the framework to version 1.5, which includes feedback from over 60 organizations and new guidance for multi-agent systems. Singapore is the only major governing jurisdiction with an effective agent-specific governance document; a governance document that is still in the process of being established by CAISI, and the EU's agent category remains undefined.
What Enterprises Should Actually Do Now?
As of yet, this isn't final guidance, but "not final" doesn't imply "not actionable." Production organizations with agents cannot wait for a standard to be published to decide on identity, logging, and access control.
Monitoring the Process and Submitting Input
As each new deliverable is produced, e.g., the initial to public draft of IR 8596, or the NCCoE's project description after the concept paper, or more RFIs issued by CAISI as the project progresses. Comments submitted to NIST-2025-0035 are already available and public; they are valuable reading as a preview of the industry consensus-building. In order to ensure operational realities are captured in guidance before it becomes the reference point for auditors, there can be no better way than to be involved in the process rather than waiting to read the final publication.
Starting Gap Analysis Before Final Guidance Lands
The technical direction is clear even without any publications so far - agent identity based on OAuth 2.0, OpenID Connect, and workload attestation (like SPIFFE/SPIRE); full list of agents, what servers they can access and what tools, and logging of enough information to give insight into an agent's decision chain after the fact, and least-privilege scoping rather than agents being granted a standing set of permissions. Doing this gap analysis now, before NIST completes its overlays, will mean the biggest effort required to find what agents and tools are really deployed throughout the environment will have to be done before NIST requirements are finalized. Agents for Akto's AI discovery feature are designed to do just that, automatically cataloging MCP servers, agents, and tools on infrastructure, cloud, and employee devices so that the inventory work doesn't have to begin from a spreadsheet.
Who Should Be Paying the Closest Attention (Regulated Sectors)
Agents deployed in the financial services, healthcare, and education sectors touch consequential decisions and sensitive data by default, and it's not just by chance that these three were named as the sectors for CAISI's listening sessions in April. Singapore's other parallel "AI missions" are advanced manufacturing, connectivity, finance and healthcare. This effort isn't "policy" news, but rather a compliance-adjacent initiative that's relevant for organizations in these sectors, and those that deploy agents in their customer-facing or transaction-executing workflows in general. The publication schedule of NIST will not slow audit and procurement cycles.
How Akto Helps Organizations Prepare for CAISI's Emerging Standards
The problem that Akto is trying to solve is the same that CAISI is attempting to standardize: As more AI agents and MCP servers enter the world, they are outpacing the ability of most security teams to monitor them and keep them under control. Through Akto's agentic AI discovery, every MCP server, AI agent, tool, and resource is automatically discovered across infrastructure, cloud, and employee devices, from over 80 connectors, and that's exactly what any future NIST identity and/or authorization overlay assumes you have as your starting inventory. Then Akto automatically sends a barrage of probes from its own "agentic red teaming" to simulate attacks on agents and MCP servers found during the test and sets guardrails and runtime protection to limit what is uncovered. Its attack matrix consists of a set of MCP attacks, which directly align with the output, input, and execution layers of frameworks such as MAESTRO and agentic Top 10 by the OWASP, while its set of identity resources includes a five-stage identity security maturity model that complements the same identification and authorization gap addressed by the NCCoE's concept paper. Akto is SOC 2, ISO, GDPR, and HIPAA compliant and has been named as an exemplary vendor by Gartner on the AI agent security market. For more information on the current status of your agent and MCP relative to the direction NIST is going, book a demo.
Final Thoughts on NIST AI Agent Standards Initiative
It is an ongoing initiative at CAISI, and there is likely to be final guidance issued in months. But the path it is going on, towards an agent that is built on existing standards in the IAM space, regular testing of the agent against known attack patterns, and a full inventory as a baseline for all others, is already clear enough to act on. If you want to stay one step ahead of where NIST's guidance is going, instead of waiting for it to be published, the first step you'll need to take is to know the type of agents and MCP servers you are running today. Akto's AI agent security platform automatically creates that inventory, performs ongoing red teaming testing, and ensures guardrails are in place to keep your agent environment from outsmarting you. Book an Agentic security demo and find out how Akto fits the identified needs for identity, discovery, and testing that will be driving CAISI's initiative.
FAQs: NIST AI Agent Standards Initiative (CAISI)
What is CAISI, and what is the AI Agent Standards Initiative?
The Center for AI Standards and Innovation (CAISI) is part of NIST's Information Technology Laboratory (ITL) and is tasked with leading NIST's AI standards activity at the national and international levels. It has a special program, the AI Agent Standards Initiative (ASI), dedicated to creating security, identity, and interoperability standards specifically for autonomous AI agents, separate from prior, more general, AI risk frameworks from NIST.
When did CAISI launch the AI Agent Standards Initiative?
This initiative was officially announced on February 17, 2026, by CAISI, along with NIST's Information Technology Laboratory and the National Science Foundation.
Why did NIST's existing AI RMF and AI 600-1 frameworks need a dedicated agent-specific initiative?
AI RMF 1.0 (2023) and the AI 600-1 Generative AI Profile (2024) were developed with human review of AI systems in mind. The specific gap that the new initiative addresses is that neither expected agents to automatically invoke tools, to chain multiple steps, nor to continue state between sessions without human (step-by-step) approval.
What are the three strategic pillars of the initiative?
Developing agent standards in an industry-led way and leading the U.S. in international standards bodies; enabling community-led open source protocol development for agents; and enabling research into AI agent security and identity infrastructure.
What did CAISI's RFI on AI agent security ask for, and when did the comment period close?
The RFI, published Jan. 8 under docket NIST-2025-0035, sought evidence regarding the agent threat landscape and mitigations; measurement methodologies; and secure development best practices. The comment period was open until March 9, 2026.
What is the identity concept paper, and how does it relate to agent authentication standards?
The report, published by the NCCoE on February 5, 2026, suggests extending existing standards, such as OAuth 2.0, OpenID Connect, SCIM, and SPIFFE/SPIRE, to provide AI agents with verifiable, auditable, non-human identities, instead of developing a new identity system.
What is NIST IR 8596 (the Cyber AI Profile), and how does it relate to this initiative?
IR 8596 is an initial draft profile that outlines how AI-specific cybersecurity considerations align with the Cybersecurity Framework 2.0's six functions and will be updated as needed. It is an overlay of already existing CSF 2.0 programs and is the compliance-mapping side of the more standards-based Agent Standards Initiative.
How does this initiative relate to OWASP, MITRE ATLAS, and MAESTRO?
These are expert-developed frameworks that tackle in detail the technical implementation aspects that are not currently covered by NIST's policy-level work. OWASP has a Top 10 list of agent-related threats and MITRE ATLAS has a comprehensive adversarial AI threat matrix, while CSA's MAESTRO threat modeling includes a multi-agent layer. All three were referred in response to RFIs to CAISI.
Does the EU AI Act currently define "agentic AI systems"?
No. Agents are not currently subject to a legal category or definition specific to agentic AI systems, but are included within the broad definition of AI systems in the Act, under the standard risk-tiered classification.
What should enterprises do now, before NIST publishes final agent security guidance?
Begin the journey of gap analysis with the visible technical direction: agent identity based on OAuth 2.0/OIDC/SPIFFE, full inventory of agents and what tools they can access, decision-level logging and least-privilege access. Comments are also made directly when open comment periods are posted.
Which industries should be paying the closest attention to this initiative?
CAISI has explicitly identified financial services, healthcare, and education as the sectors to listen to in their 2026 listening sessions. More generally, any organization that sends agents to workflows that are regulated, customer-facing, or transaction-executing should think of this as work that is near-term and relevant to compliance.
How does Akto help organizations prepare?
Akto discovers all AI agents, MCP servers, and tools in an environment, performs automated red teaming against them, and provides teams with guardrails and runtime protection - thereby eliminating the need to follow NIST's new guidelines on identity and security, which assume that there is a control layer and an inventory of all AI agents, MCP servers, and tools, and that they are protected.
Experience enterprise-grade Agentic Security solution

